Uppsats

A Comparative Security Evaluation of Manual and AI-Assisted Web Application Development

Kandidat-uppsats

Linnéuniversitetet/Institutionen för datavetenskap och medieteknik (DM)

Publicerad: 2026

Språk: Engelska

Sammanfattning

Artificial Intelligence (AI) coding assistants are increasingly used during software development, raising questions about the security of AI-generated code. This thesis examines how AI-assisted development affects the security quality of a web application developed at the bachelor’s level. To address this problem, two web applications implementing identical functionality were developed using the same technology stack. One application was developed manually, while the other was developed with assistance from ChatGPT. A controlled experimental approach was used to compare the security characteristics of the two implementations. The applications were evaluated using Zed Attack Proxy (ZAP), Snyk, and manual security review based on selected Open Web Application Security Project (OWASP) Top 10 2021 categories, including Broken Access Control, Injection, Security Misconfiguration, and Identification and Authentication Failures. The results showed that both applications exhibited several similar security weaknesses related to security configuration, session management, and request protection. While the AI-assisted application demonstrated a more structured implementation through middleware-based authentication handling, it did not significantly outperform the manually developed application in terms of security. The findings suggest that AI-assisted programming can support productivity and code organization, but secure software development still requires human oversight, security knowledge, and manual validation.

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.